Hacker News new | ask | show | jobs
by heinrich5991 3962 days ago
To the application, there's no such thing as TCP packet length. Is there a TLS packet length?
1 comments

There's a length field in a TLS record and also one in the heartbeat message itself. Heartbleed happened when the length field of the heartbeat message was longer than the length of the tls record.